{
  "osquery_time": "1592478128",
  "datetime": "2020-06-17T14:27:41.3945738Z",
  "source": "Security",
  "provider_name": "Microsoft-Windows-Security-Auditing",
  "provider_guid": "{54849625-5478-4994-a5ba-3e3b0328c30d}",
  "event_id": "4688",
  "task_id": "13312",
  "level": "0",
  "keywords": "0x8020000000000000",
  "data": "{\"EventData\":{\"SubjectUserSid\":\"S-1-5-18\",\"SubjectUserName\":\"-\",\"SubjectDomainName\":\"-\",\"SubjectLogonId\":\"0x3e7\",\"NewProcessId\":\"0x294\",\"NewProcessName\":\"C:\\\\Windows\\\\System32\\\\lsass.exe\",\"TokenElevationType\":\"%%1936\",\"ProcessId\":\"0x200\",\"CommandLine\":\"\",\"TargetUserSid\":\"S-1-0-0\",\"TargetUserName\":\"-\",\"TargetDomainName\":\"-\",\"TargetLogonId\":\"0x0\",\"ParentProcessName\":\"C:\\\\Windows\\\\System32\\\\wininit.exe\",\"MandatoryLabel\":\"S-1-16-16384\"}}",
  "computer_name": "DESKTOP-4AR7BIA"
}
